Black Kite’s 2026 Ransomware Report: Ransomware Accelerates 60% in Six Months and Shows No Signs of Slowing as New Ransomware Groups Emerge Weekly | #ransomware | #cybercrime


Report finds ransomware has evolved into a more fragmented and more operationalized ecosystem, while AI is lowering the barrier to entry for attackers and reducing the cost of ransomware operations.

BOSTON, July 21, 2026 /PRNewswire/ — Black Kite, the leader in third-party cyber risk management, today released its newest report, 2026 Ransomware Report: Why Every Year Becomes the Worst Year on Record, examining how ransomware is evolving, who is being targeted, and the externally visible risk signals organizations exhibited before they became publicly disclosed ransomware victims.

Black Kite Logo

Black Kite identified 7,551 publicly disclosed ransomware victims between April 1, 2025 and March 31, 2026, up 24.9% over the previous reporting period. But the annual figure hides a sharper trend: after tracking close to the prior year’s pace through the first half of the reporting period, ransomware victim counts accelerated 60% in the second half, closing with 861 victims in March 2026 – the highest monthly total in four years.

“Ransomware didn’t just grow this year; it evolved,” said Ferhat Dikbiyik, Chief Research & Intelligence Officer at Black Kite. “Previous years were often defined by a dominant ransomware group or a single major event. This year was different. We saw more groups enter the market, while established operators continued to scale and attack volume accelerated in the second half. Those shifts fundamentally changed the shape of the ransomware landscape.”

The report identified three key trends that defined this year’s ransomware landscape:

  • Expansion at the bottom: More than 60 new groups entered during the reporting period, more than one per week, bringing the total to 146 active groups by June 2026.

  • Concentration at the top: Despite the influx of new entrants, the five largest actors still controlled 43.6% of all victims. Qilin alone claimed 1,300+ victims, nearly twice as many as its nearest rival.

  • Acceleration in the second half: While the first half tracked close to the prior year baseline, the second half outpaced it by 60%, closing with 861 victims in March 2026, the highest monthly total in four years of tracking.

Many of the year’s most consequential attacks moved through trusted vendor platforms, including SaaS integrations, enterprise applications, OAuth connections, and support workflows.

Black Kite’s before-and-after security posture comparison also found that exposure often remained after incidents were disclosed: stealer log exposure increased 175%, while 43.5% of victims still carried critical vulnerabilities in the latest assessment.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW